Hardware-bound activation
Every activation binds the session to a device fingerprint. A leaked key stops working the moment it leaves the machine it was activated on. Device caps are enforced server-side.
Keys get shared. Builds get cracked. Licentry is the licensing API that notices and fights back: hardware-bound activations, proof-of-possession sessions, cryptographically signed responses and per-customer watermarked builds.
P-256 SIGNED RESPONSES· DPoP RFC 9449· HOSTED OR SELF-HOSTED
Licentry treats licensing as a live, signed, device-bound session, not a one-shot yes/no your attacker flips in a debugger.
Every activation binds the session to a device fingerprint. A leaked key stops working the moment it leaves the machine it was activated on. Device caps are enforced server-side.
Short-lived access tokens can be DPoP-bound to a P-256 key held by the client. A stolen token is useless without the private key that never leaves the device.
Every license response carries an ECDSA P-256 signature your app verifies against pinned public keys. A spoofed server, patched DNS or MITM'd reply fails closed.
Binaries are patched per download with a unique build token, owner hint and self-hash. When a copy leaks, one query tells you exactly which account it came from.
Concurrent-session caps, per-key device limits, heartbeat sequence tracking and geo evidence trails surface resellers and "family plans" you never approved.
A revocation bump invalidates every running session within one heartbeat. Canary keys act as honeytraps that flag cracker probing before it becomes a problem.
The whole client integration is a small, strict state machine. The order below is the order your code runs in.
vendor APIMint 28-character license keys from your dashboard or the vendor API. Keys are HMAC-peppered at rest with a pepper unique to your account, so a database leak alone reveals nothing usable.
POST /activateYour app sends the key, a device hash, and optionally a DPoP public key. It gets back a short-lived session: access + refresh tokens, signed, idempotent on retry.
POST /heartbeatA monotonic sequence counter keeps the session provably alive. Replays and skipped counters are rejected, so cloned sessions surface immediately.
POST /refreshTokens rotate before expiry. When you revoke or freeze a license, the bump invalidates every bound session on its next beat. No waiting for expiry.
// 1. activate once per install auto s = licentry.activate(key, deviceHash(), dpopJwk()); // 2. verify the response signature (pinned P-256) if (!verify(s.header("X-Licentry-Sig"), pinnedKeys)) fail_closed(); // 3. heartbeat on a timer, seq strictly increasing every(minutes(15), [&]{ licentry.heartbeat(++seq); }); // 4. refresh before expiry; re-activate on stale_revocation before(s.expiresAt, [&]{ s = licentry.refresh(s.refreshToken); }); // offline? verify the ES256 grace JWT (device-bound) if (offline && graceJwt.dev == deviceHash()) run_grace_period();
The client side is five HTTPS calls with JSON bodies, so anything with an HTTP client can run the licensing loop. Signatures are ECDSA P-256: most of these verify it straight from the standard library, the rest with one well-known package. The docs carry copy-paste examples for twelve languages.
Licentry clients can be written in C++, C#, Rust, Go, Python, Node.js, TypeScript, Java, Kotlin, Swift, C, PHP, Ruby, Dart, Objective-C, Lua, Delphi, Elixir, JavaScript, F#, Visual Basic, Scala, Clojure, Groovy, Zig, Nim, Crystal, Haskell, OCaml, Erlang, Julia, R, Perl, PowerShell, Bash and anything else that speaks HTTPS and JSON.
Every layer assumes the one above it eventually fails. That's the point: defense in depth means a cracked check still doesn't produce a working copy.
We run the API, the database, the key management and the on-call. You get an endpoint, a vendor dashboard and scoped API keys. The fastest way from zero to enforced licensing.
A single-tenant server provisioned for your account: your database, your license data, optionally your own Discord bot and API domain. We set it up by hand, harden it and keep it patched. Part of the self-hosted data plan, enabled on request.
A key on its own is a string in a database. Everything below is about what happens after the buyer has it: whether anything still checks, and what you can prove when a copy walks.
| Capability | Checkout platformsGumroad, Paddle | Licensing suitesCryptlex, LicenseSpring | Key systemsKeyAuth and similar | Licentry |
|---|---|---|---|---|
| Checks the licence while your app is running | – | ✓ | ✓ | ✓Live session |
| Ties a licence to one machine | – | ✓ | ✓ | ✓Server-enforced caps |
| Revoking kills sessions already running | –Refund only | ~Next check-in | ~Varies | ✓Within one heartbeat |
| A stolen token is useless on another machine | – | ~Uncommon | ~Uncommon | ✓DPoP, RFC 9449 |
| Your app can prove the reply really came from us | – | ~Varies | ~Varies | ✓Signed, P-256 |
| A leaked build points back to one buyer | – | ~Uncommon | ~Uncommon | ✓Watermarked download |
| Evidence when a key gets shared | – | ~Varies | ~Basic | ✓Devices, IPs, canaries |
| Works in any language, no SDK to wait for | ~Webhook only | –SDK per platform | ✓ | ✓Five HTTPS calls |
| You keep every cent you charge | –Takes a cut | ✓ | ✓ | ✓Flat monthly fee |
| Start without talking to a salesperson | ✓ | –Annual contract | ✓ | ✓From 19 dollars |
✓ does it ~ depends on the vendor or the tier – not what it is for. Columns describe the usual shape of a category rather than one product, so check the current feature list of anything you are shortlisting.
Sessions are bound to a keypair the device generates and never shares. Copy the token to another machine and it stops working, because the thief cannot sign for it.
Every session response is signed with ECDSA P-256 and verified against a key pinned in your binary. Patched DNS, a proxy or a cracked host all fail closed instead of replying "valid".
Each binary carries its own build token, owner hint and self-hash. When a copy shows up on a forum, one query names the account it was issued to.
Concurrent sessions, device counts, network changes and heartbeat gaps become a verdict you can act on, and canary keys flag people probing your product before it spreads.
They take the payment and email a key. Nothing checks that key while your software runs, so a copy posted in a forum keeps working forever. Many vendors keep theirs and add Licentry underneath: they handle checkout, we enforce the licence.
Mature suites with native SDKs, floating licences, offline activation and dongles. If you sell into enterprises with air-gapped installs and procurement paperwork, that is genuinely their ground. The cost is an SDK per platform and a sales process to get started.
Developer-first licensing over an HTTP API with a source-available core you can host yourself. Same instinct as ours: no SDK to wait for. We put our effort lower down, into the anti-tamper layer and the forensics that name the account behind a leak.
Cheap, quick to bolt on, hardware locking and reseller flows included. We cover that ground and add the hardened session protocol above, with every vendor's signing keys and key hashes sealed under their own crypto so one tenant's bad day is not everyone's.
Licentry keys are already doing real work in the wild.
Our first official partner. Belgium-based Advanced Mechanics licenses its software with Licentry: hardware-bound keys, runtime sessions and signed responses for 1,500+ customers.
advanced-mechanics.comLicentry is onboarding its first wave of vendors. Founding integrations lock their launch rate for life. Billing is crypto first, no KYC; card works through support. Every account opens as a free one-week dev trial: 1 product, 3 keys, wiped unless you subscribe.
For a first product
$19 /mo
or $150/yr (34% off)
For serious catalogs
$79$59 /mo
or $468/yr (34% off) · founding rate
Your own dedicated server, fully managed
CRYPTO BILLING, CARD VIA SUPPORT · MONTHLY OR YEARLY · NON-KYC · FOUNDING INTEGRATIONS LOCK THE LAUNCH RATE.
NEED MORE ROOM? ADD EXTRA ACTIVE LICENSES TO ANY PAID PLAN, $1 PER 100 PER MONTH, UP TO 10,000 EXTRA.
The core loop is five endpoints: validate, activate, heartbeat, refresh, logout. A minimal integration is an afternoon; adding response-signature pinning, DPoP and offline grace is typically another day. The docs walk through every step with copy-paste examples.
Anything that speaks HTTPS and JSON. There is no SDK to wait for: the client side is five endpoints. Every signature channel is ECDSA P-256 specifically so native Windows clients can verify with built-in BCrypt and no extra crypto dependencies. The docs carry working examples in twelve languages, C++, C#, Python, Node.js, Go, Rust, Java, PHP, Swift, Kotlin, Ruby and plain cURL, and you can switch the whole page to yours with one click.
Device caps stop it activating on new machines. Concurrent-session caps stop parallel use. The sharing-evidence view shows you devices, IPs and geography per key. One click bumps the revocation version and every bound session dies on its next heartbeat. If the leak was a whole binary, its watermark tells you which account it came from.
Yes. Activation can return a short-lived, device-bound offline-grace token (an ES256 JWT your app verifies locally). You choose the TTL, from 1 hour to 7 days. Revoked licenses run out of grace instead of running forever.
The self-hosted data plan gives you a dedicated server of your own. We provision it manually, secure it and keep it updated; your database and license data live there instead of on shared infrastructure, with room for as many licenses as the hardware holds. It can also run your own branded Discord bot (you hand us the token, we host and wire it up) and serve the API from your own domain once you point DNS at us. The licensing engine itself stays managed by us, so there is nothing for you to patch. Pricing is per setup since needs differ, and slots are limited because every server is maintained personally. Write to [email protected] to talk it through.
Crypto first, no KYC. You upgrade from the dashboard and pay a crypto invoice; the plan activates the moment the payment settles on-chain. If card is your only option, write to [email protected] and we handle it manually.
Integrate in an afternoon. Sleep through the next crack attempt.